mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-01 07:03:57 -05:00
User (public visibility) login can be listed on the "explore user" page by "Recently Updated" #12541
Closed
opened 2025-11-02 10:13:22 -06:00 by GiteaMirror
·
25 comments
No Branch/Tag Specified
main
release/v1.25
release/v1.24
release/v1.23
release/v1.22
release/v1.21
release/v1.20
release/v1.19
release/v1.18
release/v1.17
release/v1.16
release/v1.15
release/v1.14
release/v1.13
release/v1.12
release/v1.11
release/v1.10
release/v1.9
release/v1.8
v1.25.3
v1.25.2
v1.25.1
v1.25.0
v1.24.7
v1.25.0-rc0
v1.26.0-dev
v1.24.6
v1.24.5
v1.24.4
v1.24.3
v1.24.2
v1.24.1
v1.24.0
v1.23.8
v1.24.0-rc0
v1.25.0-dev
v1.23.7
v1.23.6
v1.23.5
v1.23.4
v1.23.3
v1.23.2
v1.23.1
v1.23.0
v1.23.0-rc0
v1.24.0-dev
v1.22.6
v1.22.5
v1.22.4
v1.22.3
v1.22.2
v1.22.1
v1.22.0
v1.23.0-dev
v1.22.0-rc1
v1.21.11
v1.22.0-rc0
v1.21.10
v1.21.9
v1.21.8
v1.21.7
v1.21.6
v1.21.5
v1.21.4
v1.21.3
v1.21.2
v1.20.6
v1.21.1
v1.21.0
v1.21.0-rc2
v1.21.0-rc1
v1.20.5
v1.22.0-dev
v1.21.0-rc0
v1.20.4
v1.20.3
v1.20.2
v1.20.1
v1.20.0
v1.19.4
v1.21.0-dev
v1.20.0-rc2
v1.20.0-rc1
v1.20.0-rc0
v1.19.3
v1.19.2
v1.19.1
v1.19.0
v1.19.0-rc1
v1.20.0-dev
v1.19.0-rc0
v1.18.5
v1.18.4
v1.18.3
v1.18.2
v1.18.1
v1.18.0
v1.17.4
v1.18.0-rc1
v1.19.0-dev
v1.18.0-rc0
v1.17.3
v1.17.2
v1.17.1
v1.17.0
v1.17.0-rc2
v1.16.9
v1.17.0-rc1
v1.18.0-dev
v1.16.8
v1.16.7
v1.16.6
v1.16.5
v1.16.4
v1.16.3
v1.16.2
v1.16.1
v1.16.0
v1.15.11
v1.17.0-dev
v1.16.0-rc1
v1.15.10
v1.15.9
v1.15.8
v1.15.7
v1.15.6
v1.15.5
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.14.7
v1.15.0
v1.15.0-rc3
v1.14.6
v1.15.0-rc2
v1.14.5
v1.16.0-dev
v1.15.0-rc1
v1.14.4
v1.14.3
v1.14.2
v1.14.1
v1.14.0
v1.13.7
v1.14.0-rc2
v1.13.6
v1.13.5
v1.14.0-rc1
v1.15.0-dev
v1.13.4
v1.13.3
v1.13.2
v1.13.1
v1.13.0
v1.12.6
v1.13.0-rc2
v1.14.0-dev
v1.13.0-rc1
v1.12.5
v1.12.4
v1.12.3
v1.12.2
v1.12.1
v1.11.8
v1.12.0
v1.11.7
v1.12.0-rc2
v1.11.6
v1.12.0-rc1
v1.13.0-dev
v1.11.5
v1.11.4
v1.11.3
v1.10.6
v1.12.0-dev
v1.11.2
v1.10.5
v1.11.1
v1.10.4
v1.11.0
v1.11.0-rc2
v1.10.3
v1.11.0-rc1
v1.10.2
v1.10.1
v1.10.0
v1.9.6
v1.9.5
v1.10.0-rc2
v1.11.0-dev
v1.10.0-rc1
v1.9.4
v1.9.3
v1.9.2
v1.9.1
v1.9.0
v1.9.0-rc2
v1.10.0-dev
v1.9.0-rc1
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.8.0-rc3
v1.7.6
v1.8.0-rc2
v1.7.5
v1.8.0-rc1
v1.9.0-dev
v1.7.4
v1.7.3
v1.7.2
v1.7.1
v1.7.0
v1.7.0-rc3
v1.6.4
v1.7.0-rc2
v1.6.3
v1.7.0-rc1
v1.7.0-dev
v1.6.2
v1.6.1
v1.6.0
v1.6.0-rc2
v1.5.3
v1.6.0-rc1
v1.6.0-dev
v1.5.2
v1.5.1
v1.5.0
v1.5.0-rc2
v1.5.0-rc1
v1.5.0-dev
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.4.0-rc3
v1.4.0-rc2
v1.3.3
v1.4.0-rc1
v1.3.2
v1.3.1
v1.3.0
v1.3.0-rc2
v1.3.0-rc1
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.2.0-rc3
v1.2.0-rc2
v1.1.4
v1.2.0-rc1
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.99
Labels
Clear labels
$20
$250
$50
$500
backport/done
💎 Bounty
docs-update-needed
good first issue
hacktoberfest
issue/bounty
issue/confirmed
issue/critical
issue/duplicate
issue/needs-feedback
issue/not-a-bug
issue/regression
issue/stale
issue/workaround
lgtm/need 2
modifies/api
modifies/translation
outdated/backport/v1.18
outdated/theme/markdown
outdated/theme/timetracker
performance/bigrepo
performance/cpu
performance/memory
performance/speed
pr/breaking
proposal/accepted
proposal/rejected
pr/wip
pull-request
reviewed/wontfix
💰 Rewarded
skip-changelog
status/blocked
topic/accessibility
topic/api
topic/authentication
topic/build
topic/code-linting
topic/commit-signing
topic/content-rendering
topic/deployment
topic/distribution
topic/federation
topic/gitea-actions
topic/issues
topic/lfs
topic/mobile
topic/moderation
topic/packages
topic/pr
topic/projects
topic/repo
topic/repo-migration
topic/security
topic/theme
topic/ui
topic/ui-interaction
topic/ux
topic/webhooks
topic/wiki
type/bug
type/deprecation
type/docs
type/enhancement
type/feature
type/miscellaneous
type/proposal
type/question
type/refactoring
type/summary
type/testing
type/upstream
Mirrored from GitHub Pull Request
No labels
type/bug
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/gitea#12541
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @inferenceus on GitHub (Feb 26, 2024).
Description
When using the web UI, user accounts can be sorted by recently updated, which leaks activity on the server for those with private repositories. This applies to both guest users who are not signed in, and users who are signed in but don't have permission to access private repositories which are leaking the activity.
To clarify, this is for users, not repositories, which are unaffected by this since updating them can't be seen due to their private status, anyway.
Gitea Version
1.21.5 / main
Can you reproduce the bug on the Gitea demo site?
Yes
@inferenceus commented on GitHub (Feb 26, 2024):
As an update to this issue, I was informed by Forgejo developers that logging in updates the
updated_unixfield. Isn't that a privacy leak itself? I don't believe logging in should expose user activity, since it pretty much equals the fact they're doing something.As for logging in, that's still uncertain as I've been able to achieve the same results just by refreshing the page. Either way, now that it's been mentioned to me, I think it's wrong for it to be handled that way. Logging in should not be exposed to non-admins.
@wxiaoguang commented on GitHub (Feb 26, 2024):
Thank you for your report. If you would like to discuss with Forgejo, you could use their issue tracker. I will update the issue report to remove unrelated contents.
Let's focus on Gitea in this space. If you really care about Privacy, you could set your visibility to Private.
@inferenceus commented on GitHub (Feb 26, 2024):
If you had read my issue, you would have seen that this affects Gitea exactly the same. It's not Forgejo-specific.
It affects Gitea.
I care about privacy. Logging in is not something the world needs to know, but there are public repositories I want them to see.
The attitude shown here makes me glad I did switch. This was a terrible response to a privacy issue. Feel free to lock this as I don't believe Gitea cares at all based on what was said. You shouldn't talk down to people as if they're stupid.
@wxiaoguang commented on GitHub (Feb 26, 2024):
Thank you for your report. But you never mentioned that you must keep your account as public visibility, right?
Since you have switched, so feel free to stay with Forgejo and tastes their bugs .....
@inferenceus commented on GitHub (Feb 26, 2024):
If it wasn't clear enough by the description, I am well aware the option exists. I already have users who do use this feature.
You mean the bugs they have fixed and you haven't? This is a bug itself, and you're not even considering it; they are. The previous security stance by Gitea has always been terrible, and now you make people pay just for proper security notices. No, thanks. That's all from me. I made the correct decision. For-profit always ends this way.
@wxiaoguang commented on GitHub (Feb 26, 2024):
To address the privacy concern, I opened a new issue for it:
-> Don't update user's last login time to avoid being listed on the explore page #29428
@inferenceus commented on GitHub (Feb 26, 2024):
Well, that's surprising. However, your attitude is not, and is unacceptable. I won't be contributing to anything related to Gitea at this point.
@wxiaoguang commented on GitHub (Feb 26, 2024):
That's pretty clear now, so I think the concern could be addressed.
Well, Forgejo doesn't really understand the security problems, for example, they didn't cherry pick some security fixes and expose the end users to potential risks. But I can't say too much publicly.
For the bugs ... I mean various bugs .... I read Forgejo PR frequently, I can see many of them has various problems ....
You could evaluate them by yourself ..... https://github.com/go-gitea/gitea/pulls?q=is%3Apr+author%3Aearl-warren+is%3Aunmerged+is%3Aclosed
@jolheiser commented on GitHub (Feb 26, 2024):
@wxiaoguang please refrain from interacting further, this is not a good conversation.
@inferenceus based on the initial report, it seems partially solved by setting activity to private. But the leak is that participating in private actions still updates "recently updated"?
Does the new issue that was opened cover your follow-up comment?
@wxiaoguang commented on GitHub (Feb 26, 2024):
Hopefully won't bother you, but for the whole context, I'd like to say something more (so I started a new comment).
First, I sincerely apologize to you for the wording making your unhappy / uncomfortable.
Some details:
@inferenceus commented on GitHub (Feb 26, 2024):
@jolheiser
This could be a solution if that's what the user wanted, but it's not what is wanted. I didn't clarify that because I was focused on the issue at hand. Instead of being asked that before anything else was stated, I received a load of nonsense in the apparent form of emotional anti-Forgejo hatred which was completely off-topic when this issue affects Gitea exactly the same.
Yes. That's the case when I don't believe it should be. I don't think a user should be forced to set their entire profile activity to private just to prevent people knowing they're using it.
Yes, it seems like it would resolve the issue if implemented.
@inferenceus commented on GitHub (Feb 26, 2024):
@wxiaoguang
Keep emotions out of this. Your attitude was ridiculous. I'm not an emotional person, I'm a logical one. I came here to help you fix a bug in your software, not for me. You treated me as if I was some dumb moron, and I don't appreciate it. I want no interaction with you, but I do want an apology.
@jolheiser commented on GitHub (Feb 26, 2024):
I am unlocking this thread and will be marking various comments as off-topic.
I think the initial request is valid.
Some comments have a mix of info and off-topic, so apologies if my marking was haphazard.
@inferenceus commented on GitHub (Feb 26, 2024):
Firstly, thank you for actually focusing on the issue at hand.
Secondly, although you weren't involved in the intial off-topic heat I had coming my way, I want to reiterate that this is the last time I will be contributing to Gitea in any form, whether it was my first time or not. I've archived this conversation for evidence purposes and will be waiting for an apology. How I was spoken to is no way to treat users, and, for Gitea's information, I had no strong bias towards Forgejo until this incident. I don't know what happened between the 2 projects, but this was enough to sway me their way.
I'd like to help Gitea users whether I use Gitea or not, but I can't willingly tolerate this attitude by the project, so I unfortunately must stay away.
@wxiaoguang commented on GitHub (Feb 26, 2024):
I have apologized: "First, I sincerely apologize to you for the wording making your unhappy / uncomfortable." https://github.com/go-gitea/gitea/issues/29425#issuecomment-1964516467
Apologize again.
@inferenceus commented on GitHub (Feb 26, 2024):
Thank you. Make sure it doesn't happen again. It was completely uncalled for. I didn't have to come here since I don't even use Gitea, but I did, because I care. I was not expecting what came to me for trying to help.
@lunny commented on GitHub (Feb 26, 2024):
Thanks for the contribution anyway. @inferenceus You already did that. :)
Let's back to the issue itself.
I have a different thought. I don't think people know whether a user just log in or did others, he just knows the person has done some activities if he was in the first one sort by recently updated.
So maybe it's not a leak? After all, users don't know what the last activity is for the user.
@jolheiser commented on GitHub (Feb 26, 2024):
In terms of privacy I think even knowing someone did "something" is related. How significant that is may vary by person.
@inferenceus commented on GitHub (Feb 26, 2024):
@lunny
It is a leak as far as I'm concerned. What use is allowing other people to know that a user logged in or did anything outside of public repositories? Would you want the world to know when you log into your PC and are moving files around etc?
@wxiaoguang commented on GitHub (Feb 26, 2024):
I think I find more problems on the "explore user" page. It accepts undocumented arguments:
https://try.gitea.io/explore/users?sort=reverselastlogin
I guess end users shouldn't care about "lastlogin" or "update time", so I propose to remove all of them.
@inferenceus commented on GitHub (Feb 26, 2024):
@wxiaoguang
I personally don't see a use case for this, either. A proposal made by the other project is to remove all sort options from the
explore/userpage, but I'm unsure if that would solve all of these issues.@wxiaoguang commented on GitHub (Feb 26, 2024):
Thank you very much for the feedback. I managed to propose a PR: Only use supported sort order for "explore/users" page #29430
For the "remove all sort options", my opinion is written in the PR:
@inferenceus commented on GitHub (Feb 26, 2024):
This is actually the best solution I've found so far for those wanting to keep those 2 specific pieces of metadata without privacy issues.
@inferenceus commented on GitHub (Feb 26, 2024):
Personally, I'm happy with the result of this issue and the pull request which was created due to it (and, hopefully, merged). Despite the heated beginning, it ended up being productive and solved what some would see as a major issue (for others, minor, but still an issue nonetheless).
Thank you @jolheiser and @wxiaoguang for resolving this issue.
Regarding the off-topic posts, to clarify at this point since it's important and should be concluded after the positive results here
When logic and rationality is used, great things can come of it. There may be people attacking this project, but I'm certainly not one of them, and it's wise to not assume everyone is unless they prove otherwise. I deal with my fair share of misinformation, so I know what it's like if what happens here is true, but I need both sides of the story to decide for myself. Regardless, it seems the developers here are good people when they focus on the issue at hand.@delvh commented on GitHub (Feb 27, 2024):
Fixed by #29430